package com.example.controller;

import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;


@RestController
@RequestMapping("demo")
public class DemoController {

    @GetMapping("hello")
//    @PreAuthorize("hasAuthority('dev:code:pull111')")
//    @PreAuthorize("@ex.hasAuthority('dev:code:pull')")
    public String hello(){
        return "hello";
    }

    //每一个接口方法上，都写死权限
}
